OpenAI Bug Disclosure Backlash: Security Community Slams CISO Before Reconciliation
Security researcher S1r1u5 (of team Hacktron) used Codex on cloud to verify a vulnerability granting access to OpenAI's internal monorepo, claiming the ability to laterally move toward model weights, datasets, and training recipes — but deliberately downloaded nothing sensitive, proved access with a harmless PR, stopped there, and followed responsible disclosure. Per their account, however, OpenAI's disclosure process was "a nightmare": the bounty amount ($6,500) wasn't the issue, but they had to consult lawyers and eventually turn to journalists to get things moving. Meanwhile, OpenAI's CISO (a former Palantir employee) was reported to have pushed for suing the researcher, sparking community mockery of OpenAI for "embracing the security community" in words while wielding legal threats in practice. Per LiveOverflow, the CISO has since reached out to apologize and the two sides reconciled.
Confirmed
- The researcher verified a vulnerability granting access to OpenAI's internal repo, proved it with a harmless PR, stopped, and followed responsible disclosure (m5)
- The researcher described OpenAI's disclosure process as difficult, requiring lawyers and journalists; the bounty was $6,500 (m3)
- LiveOverflow says OpenAI's CISO proactively apologized, the two sides reconciled, and notes his earlier critical tweet thread was personal opinion (m6, m8)
- Hacktron founder S1r1u5 clarified it was not Claude Code autonomously hacking OpenAI — the key was human researcher rootxharsh's expertise (m14)
- White-hat hacker s1r1us clarified: finding a vulnerability doesn't mean knowing how to protect such a complex organization; OpenAI has a more professional security team (m12)
Unconfirmed
- Whether the CISO actually advocated suing the researcher — this mainly comes from secondhand reposts, with no original first-hand source
- Any formal commitment by OpenAI to fix its disclosure process — not seen in the materials
Why it matters
- Security veteran Robert Graham criticized OpenAI and Anthropic for abandoning the cybersecurity community's 40-year principle of encouraging open disclosure and opposing retaliation (m2); researcher IceSolst argued that capable hackers coming forward voluntarily was a golden trust-building opportunity that OpenAI burned, and the CISO should be replaced over it (m11)
- The incident sparked a methodology debate: Tal BeerySec argued a 0-day should receive responsible disclosure rather than lateral movement, calling the PR filed in OpenAI's GitHub repo "over the line" (m13); jachiam0 (former OpenAI red teamer, now Anthropic) argued responsible disclosure should be supported even beyond bug bounty scope, dismissed attacks on the CISO as "complete distortions," and noted he had already warned about Slack lateral-movement risks (m7, m9, m10)
- Joshua Saxe used the episode to mock OpenAI's security maturity as resembling a recklessly scaling company (m4), underscoring the systemic tension between frontier AI companies' security practices and the external research community
2026-09-19 ~ 2026-09-21 · 14 related posts
- Episode 1: Three Hacktron Researchers Breach OpenAI's Internal Systems Using Claude Opus 5(2026-09-18, 59 posts)
- Episode 2: Hacktron AI Chained Two Bugs to Take Over OpenAI Accounts in 72 Hours; $6,500 Bounty Sparks Outcry(2026-09-18, 19 posts)
- Episode 3: Nathan Lambert: Closed-Source Models Are the True Tip of the AI Risk Iceberg(2026-09-18, 6 posts)
- Episode 4: OpenAI Bug Disclosure Backlash: Security Community Slams CISO Before Reconciliation(2026-09-19, 14 posts)
Primary sources
- LiveOverflow threads critique of how OpenAI's CISO fumbled the situation — xeophon · 2026-09-19
- Security researchers blast OpenAI's "nightmarish" vulnerability disclosure process — evilsocket · 2026-09-19
- Security researchers slam OpenAI for burning trust over unreported vuln chain outreach — evilsocket · 2026-09-20
- Hacktron-OpenAI Security Drama: Insider Says OpenAI's Security Maturity Is Blitzscale-Level — joshua_saxe · 2026-09-20
- OpenAI safety researcher slams CISO pile-on over HacktronAI breach as 'total distortion' — jachiam0 · 2026-09-20
- jachiam0 doubles down: Slack logs at every major AI lab enable lateral movement, signed S3 URLs included — jachiam0 · 2026-09-20
- [source] LiveOverflow says OpenAI CISO apologized over vulnerability disclosure fumble — xeophon · 2026-09-20
- Hacktron Founder: Claude Code Didn't Hack OpenAI Alone — Human Zero-Day Intuition Was Key — gowthami_s · 2026-09-20
- OpenAI CISO mocked for reportedly wanting to 'threaten to sue' security researchers — kevinnbass · 2026-09-20
- [source] White hat who breached OpenAI says frontier labs' security is alarmingly weak — Miles_Brundage · 2026-09-20
- Security veterans slam OpenAI and Anthropic for threatening researchers and discarding 40 years of disclosure norms — AlexTensor · 2026-09-20
- OpenAI vulnerability disclosure debate: researcher defends hack despite scope limits — jachiam0 · 2026-09-21
- Security Row: Was the 0-Day PR in OpenAI's GitHub Repo Responsible Disclosure or a Bridge Too Far? — joshua_saxe · 2026-09-21
- [source] OpenAI bug disclosure sparks CFAA debate as researcher defends good-faith repo access test — ns123abc · 2026-09-21